<!-- llms-explorer concept facts · https://llms-explorer.com/tree/mongodb-atlas-iam-and-rbac/ · pack 2026-09-08 · ~4408 tokens -->

# MongoDB Atlas IAM and RBAC

> Atlas uses a three-tier identity model: Organization → Project → Database.

Parent: [MongoDB Atlas](https://llms-explorer.com/tree/mongodb-atlas/) · 18 facets · 74 facts · page: https://llms-explorer.com/tree/mongodb-atlas-iam-and-rbac/

## Three-Tier Identity Model

- Atlas uses a three-tier identity model: Organization → Project → Database. — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#three-tier-identity-model)

## SCRAM-SHA-256 (default)

- Username + password. Most compatible. FIPS 140-2 compliant when using SHA-256. — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#scram-sha-256-default)

## X.509 Certificates

- Client certificate authentication. Two types: — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#x509-certificates)
  - Atlas-managed: Atlas generates and manages the CA; valid for up to 5 years (configurable) — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#x509-certificates)
  - Customer-managed (LDAP): Customer operates their own CA; Atlas validates against customer's CA — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#x509-certificates)

## AWS IAM (MONGODB-AWS)

- Passwordless auth using AWS credentials (IAM user, role, EC2 instance profile, IRSA, Lambda execution role). — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#aws-iam-mongodb-aws)
- Connection string: authMechanism=MONGODB-AWS — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#aws-iam-mongodb-aws)
- Create Atlas database user with username = arn:aws:iam::<account-id>:role/<role-name> or arn:aws:iam::<account-id>:user/<username> — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#aws-iam-mongodb-aws)

## OIDC / Workload Identity Federation (GA 2024)

- Workforce (human users) and Workload (apps/services) identity federation. — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#oidc-workload-identity-federation-ga-2024)
- Workforce OIDC: Human users SSO into Atlas database access via Entra ID, Okta, Google Workspace, or any OIDC provider. — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#oidc-workload-identity-federation-ga-2024)
- Workload OIDC: Applications authenticate without passwords using OIDC tokens from GCP, Azure, AWS, or any OIDC provider. — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#oidc-workload-identity-federation-ga-2024)

## LDAP (Deprecated in MongoDB 8.0)

- LDAP authentication and authorization supported in MongoDB 4.x–7.x. Deprecated in 8.0. Migrate to OIDC or X.509. — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#ldap-deprecated-in-mongodb-80)

## Atlas Service Accounts (GA April 2025)

- Replaces legacy Programmatic API Keys for machine-to-machine Atlas API access. — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#atlas-service-accounts-ga-april-2025)
  - Client ID + Client Secret → OAuth 2.0 client credentials flow → 1-hour bearer tokens — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#atlas-service-accounts-ga-april-2025)
  - Scoped at Org or Project level — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#atlas-service-accounts-ga-april-2025)
  - Supports Workload Identity Federation (WIF) - replace Client Secret with OIDC tokens from GKE/AKS/EKS/Cloud Run — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#atlas-service-accounts-ga-april-2025)
- Migration from API Keys to Service Accounts: — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#atlas-service-accounts-ga-april-2025)
  - Create Service Account in Atlas (Org/Project → Access Manager → Service Accounts) — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#atlas-service-accounts-ga-april-2025)
  - Generate Client ID + Client Secret (show once) — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#atlas-service-accounts-ga-april-2025)
  - Update IaC/CI env vars: MONGODB_ATLAS_CLIENT_ID + MONGODB_ATLAS_CLIENT_SECRET — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#atlas-service-accounts-ga-april-2025)
  - Remove old API key after confirming new SA works — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#atlas-service-accounts-ga-april-2025)

## Programmatic API Keys (Legacy)

- Public key + private key pair using HTTP Digest. Cannot be rotated atomically. Counted as "users" in the project. Will eventually be deprecated. — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#programmatic-api-keys-legacy)
- API key IP allowlist: API keys can be restricted to specific IP addresses - important for CI/CD security. — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#programmatic-api-keys-legacy)

## Workforce Identity Federation (SAML/OIDC)

- Allows organization members to log into the Atlas UI and API using their corporate SSO (Okta, Entra ID, Google Workspace, PingFederate). — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#workforce-identity-federation-samloidc)
- SAML: Atlas UI access only. Configure via Organization → Security → Federation Management. — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#workforce-identity-federation-samloidc)
- OIDC (Workforce): Atlas database access. Configure in Organization → Security → Workforce Identity Provider. Maps IdP group claims to Atlas project roles. — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#workforce-identity-federation-samloidc)
- Group-to-role mapping: Map IdP group Object IDs to Atlas org/project roles. Groups claim must be present in the token. Large group membership (>150 groups on Entra ID) may omit groups claim - filter to relevant groups. — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#workforce-identity-federation-samloidc)

## Custom Database Roles

- Extend built-in MongoDB roles with collection-level or action-level granularity. — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#custom-database-roles)
- Custom roles created at the project level - available across all clusters in the project. — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#custom-database-roles)

## Atlas Resource Policies (Cedar Guardrails)

- Atlas Resource Policies use Cedar policy language to enforce organization-wide guardrails (GA 2025). Examples: — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#atlas-resource-policies-cedar-guardrails)
  - Restrict cluster creation to specific cloud providers/regions — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#atlas-resource-policies-cedar-guardrails)
  - Require encryption at rest for all clusters — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#atlas-resource-policies-cedar-guardrails)
  - Enforce minimum backup retention — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#atlas-resource-policies-cedar-guardrails)
- Applied at the organization level; evaluated before any Atlas API mutation. — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#atlas-resource-policies-cedar-guardrails)

## Database Auditing

- When available: M10+ clusters only. Not available on M0/Flex. — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#database-auditing)
- Configure audit log filter to capture: authenticate, authCheck (authorization decisions), createCollection, dropCollection, createDatabase, dropDatabase. — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#database-auditing)
- SIEM integration: Push Atlas audit logs to Datadog, Sumo Logic, S3, or via Atlas Admin API log pull. — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#database-auditing)
- Activity Feed: Organization and project-level audit trail of Atlas control-plane actions (cluster creates, user changes, backup events) - accessible even on M0/Flex. — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#database-auditing)

## Common Debugging Scenarios

- "Authentication failed" for new database user: — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#common-debugging-scenarios)
  - Verify user exists in the correct project (users are project-scoped) — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#common-debugging-scenarios)
  - Verify the auth database is admin for SCRAM users — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#common-debugging-scenarios)
  - Verify password does not contain special characters needing URL encoding — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#common-debugging-scenarios)
  - Verify IP allowlist includes the client IP — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#common-debugging-scenarios)
- "Authorization failed" after auth succeeds: — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#common-debugging-scenarios)
  - Check which roles are assigned to the user — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#common-debugging-scenarios)
  - Verify role is scoped to the correct database/collection — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#common-debugging-scenarios)
  - Custom roles: check actions and resources are correct — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#common-debugging-scenarios)
  - AWS IAM: verify the role ARN matches exactly (account ID + role name) — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#common-debugging-scenarios)
- OIDC token rejected: — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#common-debugging-scenarios)
  - Decode JWT: check iss claim matches Atlas Workload IDP issuer config — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#common-debugging-scenarios)
  - Check aud claim matches Atlas IDP audience field — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#common-debugging-scenarios)
  - Check token exp hasn't passed (clock skew > 5 min causes failures) — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#common-debugging-scenarios)

## References

- Atlas Database Users — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#references)
- Atlas Service Accounts — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#references)
- Workforce Identity Federation — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#references)
- Workload Identity Federation — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#references)
- Atlas Resource Policies — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#references)
- Database Auditing — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-atlas-iam-rbac/#references)

## Where this helps

- Designing passwordless, machine-to-machine authentication for an application running on AWS, GCP, or Azure compute, using AWS IAM or OIDC Workload Identity Federation instead of static database credentials. — [source](https://llms-explorer.com/tree/mongodb-atlas-iam-and-rbac/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Migrating CI/CD and IaC automation off legacy Programmatic API Keys onto Atlas Service Accounts with OAuth 2.0 client credentials. — [source](https://llms-explorer.com/tree/mongodb-atlas-iam-and-rbac/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Rolling out corporate SSO, such as Okta or Entra ID, for human access to both the Atlas UI and the underlying databases via Workforce Identity Federation. — [source](https://llms-explorer.com/tree/mongodb-atlas-iam-and-rbac/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Debugging an "Authorization failed" error after authentication succeeds, which usually traces to role scope, custom-role actions, or, for OIDC, a claims/audience mismatch. — [source](https://llms-explorer.com/tree/mongodb-atlas-iam-and-rbac/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*

## Project ideas

- Migrate a CI/CD pipeline from legacy Programmatic API Keys to an Atlas Service Account using OAuth 2.0 client credentials, and add Workload Identity Federation so no client secret is stored at all. — [source](https://llms-explorer.com/tree/mongodb-atlas-iam-and-rbac/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Design a custom database role that grants collection-level, action-level access narrower than any built-in role, for a service that should only read one collection. — [source](https://llms-explorer.com/tree/mongodb-atlas-iam-and-rbac/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Build an org-wide Atlas Resource Policy (Cedar guardrail) that restricts cluster creation to approved cloud providers/regions and requires encryption at rest. — [source](https://llms-explorer.com/tree/mongodb-atlas-iam-and-rbac/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Set up Workforce OIDC federation so engineers authenticate to database access with their corporate SSO identity instead of a shared SCRAM credential. — [source](https://llms-explorer.com/tree/mongodb-atlas-iam-and-rbac/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*

## Antipatterns

- Continuing to build new integrations on LDAP authentication, which is deprecated as of MongoDB 8.0 in favor of OIDC or X.509. — [source](https://llms-explorer.com/tree/mongodb-atlas-iam-and-rbac/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Relying on legacy Programmatic API Keys for new automation instead of Service Accounts, when API keys can't be rotated atomically and count as project "users." — [source](https://llms-explorer.com/tree/mongodb-atlas-iam-and-rbac/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Mapping an OIDC group claim without accounting for large group membership — Entra ID can omit the groups claim entirely above roughly 150 groups, silently breaking group-to-role mapping. — [source](https://llms-explorer.com/tree/mongodb-atlas-iam-and-rbac/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Treating Atlas users and database users as the same identity — they access different planes, control plane vs. data plane, and have to be reasoned about separately. — [source](https://llms-explorer.com/tree/mongodb-atlas-iam-and-rbac/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*

## Known issues

- Database Auditing is only available on M10+ clusters, not on M0 or Flex, so audit-log-based compliance controls can't be applied uniformly across every tier. — [source](https://llms-explorer.com/tree/mongodb-atlas-iam-and-rbac/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- X.509 customer-managed certificates require the customer to operate their own CA, which adds real operational burden compared to Atlas-managed certificates that are valid up to 5 years. — [source](https://llms-explorer.com/tree/mongodb-atlas-iam-and-rbac/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- OIDC token failures are commonly caused by clock skew greater than about 5 minutes between the token issuer and Atlas, which can look like a configuration bug rather than a clock problem. — [source](https://llms-explorer.com/tree/mongodb-atlas-iam-and-rbac/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Custom database roles are created at the project level, so a role designed for one project has to be recreated, not simply shared, in another project. — [source](https://llms-explorer.com/tree/mongodb-atlas-iam-and-rbac/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*

## Context files

- [MongoDB Atlas IAM and RBAC](https://llms-explorer.com/downloads/sources/mdb-context-hub/mongodb-atlas-iam-rbac.md)
